Permissions
The section is intended to search, issue, revoke and suspend permissions.
Search
Enter a user, account, resource, or description in the search string and click .
Click Extended search, set one or more filters and click Search.
Create
To be able to manage permissions you need the Permissions management privileges.
In the Permissions section, click Create.
(Optional) Select an organizational unit and click Select.
Define the permission scope.
More about permission scope
Select who gets access:
- Users — the permission is granted to one or several selected users.
- User group — the permission is granted to one selected user group.
Select what to get access to:
Resources — the permission is granted to one or several selected resources.
Resource groups — the permission is granted to one selected resource group.
Ad hoc connections — the permission is granted to Ad hoc resources with the selected connection type, including resources not registered in PAM. One shared account is used for all connection types.
Click Next.
Select the account under which the user will open a session on the resource:
- Select account in PAM — the permission is granted to an account added to Axidian Privilege.
- Use user account — the permission is granted to an arbitrary account.
The user needs to enter the login and password of the account on the resource. In RDP and SSH sessions, it is possible to log in using the current Axidian Privilege user credentials.
(Optional) Configure access to credentials.
More about access settings
You can grant access to credentials only at the permission creation step.
The following settings are available:
- Credentials — the option defines actions with credentials:
- Allow view account credentials — users can view passwords of the accounts from this permission.
- Allow change account credentials — users can change passwords of the accounts from this permission.
- Allow running pamsu in SSH sessions — the setting defines access to PamSU when connecting via SSH Proxy:
- Managed by policies — access to PamSU is determined by the policy of the resource for which the permission is granted.
- Allowed — the user can use PamSU regardless of policy settings.
- Denied — the user is not allowed to use PamSU regardless of policy settings.
- Credentials — the option defines actions with credentials:
(Optional) Fill in the Description field.
(Optional) Configure time restrictions.
More about time restrictions
You can set a schedule according to which users are allowed to open sessions or change credentials. For example, you can grant permission to work only on weekdays from 8:00 to 17:00.
The following settings are available:
Validity period — the time period during which the permission is valid. For example, you can grant permission for one day or month.
Begin — set the date and time when the permission becomes active.
If only Begin is set, the permission will become active on the selected date, and its validity period will be unlimited.End — set the date and time when the permission becomes inactive.
If only End is set, the permission will become active at the moment of creation, but will be suspended on the specified date.infoIf the Begin and End parameters are not set, the permission will be valid indefinitely.
Access schedule — restrictions by days of the week taking into account the specified schedule.
Allow access only on selected days — select the days of the week when the permission will be active.
Allow access only during selected hours — select the time when the permission will be active.
infoAccess by days of week is granted according to the management server time zone.
After the validity period expires, the permission will transition to the Restricted/Inactive state, and the user session will be terminated.
In the Connection source setting, select the network address from which sessions to the resource are allowed to be opened.
If no network locations are added to PAM, the value is set to No restrictions — the permission can be used from any device on the network.Check the data and click Create permission.
Create copy
You can create a copy of any permission, while the original permission can be revoked or suspended. When copying, a creation window opens with the parameters of the original permission set. This selection can be edited: change the resource, remove users, or set restrictions.
If a user, application, resource, or account from the original permission is unavailable, they will not be added to the new permission.
To copy a permission:
- Go to the profile of the desired permission and click Create copy.
- Select an action for the original permission:
- Keep — the original permission will remain active.
- Suspend — the original permission will become unavailable for use and will transition to the Suspended status.
- Revoke — the original permission will be revoked and will transition to the Revoked status.
- Make changes to the original permission.
- Check the data and click Create permission.
Revoke
Click Revoke and revoke a permission that is no longer needed. Users lose access immediately, not after the session ends.
To revoke multiple permissions, in the Permissions section select the desired permissions and click Revoke.
Revoked permissions cannot be restored.
If you need to temporarily prohibit the use of a permission, suspend it.
Revoked permissions stop displaying in the Permissions section, but they can be found using search:
- Go to the Permissions section.
- Open Extended search.
- Select the Revoked status and click Search.
Suspend
Click Suspend in the permission profile to temporarily prohibit using the permission. Users lose access immediately, not after the session ends.
To suspend multiple permissions, in the Permissions section select the required permissions and click Suspend.
Reactivate
Click Reactivate in the permission profile to activate a suspended permission. The permission will change to the Valid state.
To activate multiple permissions, in the Permissions section select the required permissions and click Reactivate.
Generate report
A report is an export of permissions based on specified filters. For example, you can generate a report on revoked permissions or export a list of all permissions for a specific user. By default, the report includes up to 50,000 records, but this limit can be increased.
To generate a report:
- Go to the Permissions section.
- (Optional) Enter a query in the search bar or apply extended search filters.
- Click Generate report.
- In the dialog that appears, select the CSV or XLSX format.
The report with the specified filters is generated in the background. Download the report in the Report history section.